Improper Input Validation in Samsung Products Allows Network Restriction Bypass
CVE-2026-20974
5.2MEDIUM
What is CVE-2026-20974?
An improper input validation vulnerability exists in various Samsung devices that allows physical attackers to exploit data related to network restrictions. This issue enables attackers to bypass Carrier Relock mechanisms, potentially facilitating unauthorized access to the device. Users should ensure their devices are updated to the latest security release to mitigate the risk associated with this vulnerability.
Affected Version(s)
Samsung Mobile Devices SMR Jan-2026 Release in Selected Android 13, 14, 15, 16 devices